VYPR
Medium severity5.9NVD Advisory· Published May 7, 2025· Updated Apr 23, 2026

CVE-2025-47615

CVE-2025-47615

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flowdee Amazon Product in a Post amazon-product-in-a-post-plugin allows Stored XSS.This issue affects Amazon Product in a Post: from n/a through <= 5.2.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in WordPress Amazon Product in a Post plugin up to v5.2.2 allows authenticated attackers to inject malicious scripts.

The vulnerability is a stored Cross-Site Scripting (XSS) flaw in the Amazon Product in a Post plugin for WordPress, affecting versions through 5.2.2. The root cause is improper neutralization of user-supplied input during web page generation, allowing malicious scripts to be stored in the database and later executed in the context of a victim's browser [1].

Exploitation requires an authenticated user with at least contributor-level privileges to inject crafted payloads via the plugin's input fields. The attacker does not need direct victim interaction to store the payload; however, according to the advisory, user interaction (such as the victim visiting a modified page) is necessary for the script to execute [1]. This distinction is typical for stored XSS, where the stored script triggers automatically upon page load.

The impact includes the ability to inject arbitrary HTML and JavaScript, leading to redirections, unwanted advertisements, or other malicious actions when guests visit compromised pages. Attackers could leverage this for session hijacking, phishing, or site defacement, potentially affecting thousands of sites due to mass-exploit campaigns targeting WordPress plugins [1].

As a mitigation, users should immediately update the Amazon Product in a Post plugin to the latest patched version beyond 5.2.2. The developer has not released a workaround, and no reliable alternative exists [1]. Given the active exploitation risk, site administrators are urged to prioritize this update.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.